Security
Security is a system of boundaries, evidence and failure modes.
The platform is designed to minimize privilege, preserve operational evidence and make configuration-dependent controls explicit rather than silently pretending they exist.
Identity & access
Enterprise roles, tenant scope, SSO control plane, verified domains and lifecycle controls.
Audit integrity
AUD-2.0 records append-only compliance events with payload, previous and event hashes, then verifies the chain periodically.
Secrets & credentials
API keys are stored as hashes; runtime secrets are kept outside readable business entities.
Data boundaries
Organization, workspace and department identifiers define scope across sensitive entities and backend functions.
API governance
Scopes, entitlement enforcement, rate limiting, idempotency and outbound webhook protections constrain integrations.
Operational evidence
Readiness, pilot, observability and rollback controls create evidence around production operation, not just feature availability.
What the platform can state today
Technical controls implemented in the product can be inspected in the Trust Center and documentation. Those controls do not automatically create an organizational certification, legal compliance opinion or contractual availability commitment.
What remains organization-dependent
External IdP configuration, SCIM secrets, webhook signing secret, HMAC audit secret, legal privacy documents, subprocessors, RPO/RTO and contractual SLA require separate configuration, governance or approval.